VYPR
High severity7.1NVD Advisory· Published Mar 16, 2026· Updated Apr 9, 2026

CVE-2026-26133

CVE-2026-26133

Description

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Affected products

20
  • cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:android:*:*range: <16.0.19815.10000
    • cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:iphone_os:*:*range: <2.107.2
  • Microsoft/Edge2 versions
    cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:*range: <145.3800.99
    • cpe:2.3:a:microsoft:edge:*:*:*:*:*:iphone_os:*:*range: <145.3800.99
  • Microsoft/Excel2 versions
    cpe:2.3:a:microsoft:excel:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:microsoft:excel:*:*:*:*:*:android:*:*range: <16.0.19822.20038
    • cpe:2.3:a:microsoft:excel:*:*:*:*:*:iphone_os:*:*range: <2.106.2
  • cpe:2.3:a:microsoft:loop:*:*:*:*:*:iphone_os:*:*
    Range: <2.106
  • Microsoft/Onenote2 versions
    cpe:2.3:a:microsoft:onenote:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:microsoft:onenote:*:*:*:*:*:android:*:*range: <16.0.19725.20142
    • cpe:2.3:a:microsoft:onenote:-:*:*:*:*:iphone_os:*:*
  • Microsoft/Outlook3 versions
    cpe:2.3:a:microsoft:outlook:*:*:*:*:*:android:*:*+ 2 more
    • cpe:2.3:a:microsoft:outlook:*:*:*:*:*:android:*:*range: <5.2605.0
    • cpe:2.3:a:microsoft:outlook:*:*:*:*:*:iphone_os:*:*range: <5.2605.0
    • cpe:2.3:a:microsoft:outlook:-:*:*:*:*:macos:*:*
  • cpe:2.3:a:microsoft:power_bi:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:microsoft:power_bi:*:*:*:*:*:android:*:*range: <2.2.260210.21290750
    • cpe:2.3:a:microsoft:power_bi:-:*:*:*:*:iphone_os:*:*
  • cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:android:*:*range: <16.0.19822.20038
    • cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:iphone_os:*:*range: <2.106.2
  • Microsoft/Teams2 versions
    cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:*range: <1.0.0.2026043102
    • cpe:2.3:a:microsoft:teams:*:*:*:*:*:iphone_os:*:*range: <8.3.1
  • Microsoft/Word2 versions
    cpe:2.3:a:microsoft:word:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:microsoft:word:*:*:*:*:*:android:*:*range: <16.0.19822.20038
    • cpe:2.3:a:microsoft:word:*:*:*:*:*:iphone_os:*:*range: <2.106.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

17